On Fri, Mar 07, 2008 at 12:49:45PM -0600, Nicolas Williams wrote:
> On Fri, Mar 07, 2008 at 12:45:19PM -0600, Brian Cameron wrote:
> > Nicholas:
> > >I should note that making use of Solaris privileges to help build a
> > >trusted path between the screen lock process and the X11 server would
> > >mean that the screen lock process must run on the same system as the X11
> > >server because getpeerucred(3C) doesn't work remotely [yet].
> > 
> > But the Xserver also runs as the user.  The login program does some
> > handshaking with the Xserver to make it drop to user perms after
> > the user authenticates.
> 
> Not quite:

Of course, this is my desktop, which is running build 62, which is old.
My laptop runs a much more recent build, but it's at home.

Reply via email to